News:

Want to get involved in developing SMF? Why not lend a hand on our GitHub!

Main Menu

Using BBcode or HTML in forum descriptions issues

Started by Hathor, April 04, 2015, 02:02:18 PM

Previous topic - Next topic

Hathor

Hello,

I just installed a clean version of 2.1 and have finished adding the forums. I want to add, in the forum description, a brief bullet list of what topics are covered in that respective forum but i can't seem to get BBcode or HTML to work. Is there an on switch for this, or does the forum not support this?

Kindred

I do not believe that you are allowed to use bbc or html in the board descriptions for 2.1

And the FORUM description has NEVER allowed any formatting.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Illori

Quote from: Kindred on April 04, 2015, 02:15:40 PM
I do not believe that you are allowed to use bbc or html in the board descriptions for 2.1

And the FORUM description has NEVER allowed any formatting.

that was changed for the group member name, i am not sure that was changed for board descriptions.

Kindred

it should have been...  if it has not been changed, it should be
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Illori



html in a board description seems to work just fine.

Kindred

it should have been removed... and since it was not, it still should be

html should no longer be allowed in board descriptions or membergroup names
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Illori

why should it be no longer be allowed in board descriptions? very few people use it in board descriptions and it does not cut off like the membergroup name does.

Arantor

Because anyone with manage boards permissions can XSS their way to account hijack.
Holder of controversial views, all of which my own.


Kindred

exactly...  we've already had this discussion. It's a security issue - as well as a point which, invariably leads people to  come here complaining that it screws up their layouts...
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Illori

then i guess an issue on github has to be opened or a topic for the dev team so we make sure they are aware.

Antes

Quote from: Arantor on April 05, 2015, 07:24:36 AM
Because anyone with manage boards permissions can XSS their way to account hijack.

is it worth (or not) to limit HTML usage to basic level (like in post?) or it won't solve the problem as well ?

Arantor

At what point do you limit it though? Do you keep it to something really simple like basic formatting and maybe images, or do you go for 'everything bbc supports' and then fight with BBC parsing performance?
Holder of controversial views, all of which my own.


Kindred

Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Illori

Quote from: Kindred on April 05, 2015, 02:55:46 PM
Kill it all.

i dont think we should stop bbc from being used. look at our list of boards and their descriptions, we have links in some of them. if no bbc allowed then that would have to be removed.

Hathor

I suppose we all have different interpretations of where something becomes a security risk, but formatting and allowing transfering of data are two different things. Allowing formatting such as bold, italics, underline, table, bullet points etc can't be much of a security issue. Otherwise it should be removed alltogether from the forum software.

Arantor

This is why bbcode is even a thing in the first place - it's not HTML. You can't add arbitrary JavaScript in it unless you're actually the administrator.

Here, though, adding arbitrary JS can be done by a theoretically non-administrative user.
Holder of controversial views, all of which my own.


Advertisement: